Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) submitted a letter to the House Energy & Commerce Committee opposing a provision in the Committee's budget reconciliation bill that would impose a 10-year moratorium on enforcement of state artificial intelligence and automated decisionmaking technology (ADMT) laws and regulations. The CPPA argues that the moratorium threatens critical consumer protections approved by California voters under the CCPA, including regulations governing consumers' access and opt-out rights related to businesses' use of ADMT.

LowAI/Automated Decisions
HHSEnforcement Action

Washington Gastroenterology

Washington Gastroenterology (Healthcare Provider, WA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) opened a formal public comment period on modifications to proposed regulations for CCPA updates, cybersecurity audits, risk assessments, Automated Decisionmaking Technology (ADMT), and insurance companies. The modifications were approved unanimously during the May 1 Board Meeting, and comments are accepted until June 2, 2025.

LowNotice FailureConsent FailureSecurity Failure
HHSEnforcement Action

Blue Cross Blue Shield of Texas

Blue Cross Blue Shield of Texas (Business Associate, IL) reported a HIPAA breach affecting 593 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
CPPAFine

Jerico Pictures, Inc., d/b/a National Public Data(National Public Data)

The California Privacy Protection Agency ordered Jerico Pictures, Inc., doing business as National Public Data, to pay a $46,000 fine for failing to register and pay the annual fee required under the Delete Act. The order was issued by default after the company did not contest the allegations, highlighting CPPA's enforcement of data broker registration requirements.

LowData Broker Non-Compliance

$46K

CPPAFine

Jerico Pictures, Inc.(National Public Data)

The California Privacy Protection Agency (CPPA) ordered Jerico Pictures, Inc., doing business as National Public Data, to pay a $46,000 fine for failing to register and pay the annual fee required under California's Delete Act. The order was issued by default after the company did not contest the allegations. This enforcement action highlights the CPPA's efforts to ensure data broker compliance with registration laws.

LowData Broker Non-Compliance

$46K

HHSEnforcement Action

Allied Services Division Welfare Fund

Allied Services Division Welfare Fund (Health Plan, IL) reported a HIPAA breach affecting 5,727 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
TXWarning Letter

TP-Link, Alibaba, CapCut, and several other CCP-affiliated Chinese companies

Texas Attorney General Ken Paxton issued a 30-day compliance notice to TP-Link, Alibaba, CapCut, and other CCP-affiliated Chinese companies for violating the Texas Data Privacy and Security Act (TDPSA). The companies are accused of failing to disclose consumer data processing activities, allow opt-out of data collection, and enable consumer data deletion as required by Texas law. If the companies do not comply within 30 days, the Attorney General's office will pursue additional legal action.

LowNotice FailureOpt-Out Failure
HHSEnforcement Action

The Carpenter Health Network

The Carpenter Health Network (Healthcare Provider, LA) reported a HIPAA breach affecting 878 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXEnforcement Action

TP-Link, Alibaba, CapCut

Texas Attorney General Ken Paxton has issued notices to several Chinese companies, including TP-Link, Alibaba, and CapCut, for violating the Texas Data Privacy and Security Act (TDPSA). The companies must comply with TDPSA's requirements to disclose data processing, allow opt-outs, and enable data deletion within 30 days, or face further legal action.

LowNotice FailureOpt-Out FailureUnauthorized Data Sharing
TXEnforcement Action

TP-Link, Alibaba, CapCut, and several other Chinese and Chinese Communist Party (“CCP”) aligned companies(TP-Link, Alibaba, CapCut)

Texas Attorney General Ken Paxton announced legal action against several Chinese companies, including TP-Link, Alibaba, and CapCut, for violating the Texas Data Privacy and Security Act (TDPSA). The companies have been given 30 days to comply with requirements to disclose data processing, allow consumers to opt out of data collection, and enable data deletion. Failure to comply will result in further legal action to protect Texans' privacy rights and prevent data from being accessed by the Chinese Communist Party.

LowNotice FailureOpt-Out FailureUnauthorized Data Sharing
TXEnforcement Action

TP-Link, Alibaba, CapCut, and several other Chinese and Chinese Communist Party ("CCP") aligned companies(TP-Link, Alibaba, CapCut)

Texas Attorney General Ken Paxton has notified several Chinese companies, including TP-Link, Alibaba, and CapCut, that they are violating the Texas Data Privacy and Security Act (TDPSA). The companies must comply with TDPSA requirements to disclose data processing, allow consumer opt-outs, and enable data deletion within 30 days. Failure to comply will result in further legal action.

LowNotice FailureOpt-Out FailureUnauthorized Data Sharing
HHSEnforcement Action

SunLink Health Systems, Inc.

SunLink Health Systems, Inc. (Healthcare Provider, GA) reported a HIPAA breach affecting 2,856 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Minnesota Orthodontics and Dentofacial Orthopedics, P.A.

Minnesota Orthodontics and Dentofacial Orthopedics, P.A. (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Monongalia Health System, Inc.

Monongalia Health System, Inc. (Healthcare Provider, WV) reported a HIPAA breach affecting 4,895 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

CardioVascular Health Clinic

CardioVascular Health Clinic (Healthcare Provider, OK) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

DermCare Management

DermCare Management (Business Associate, FL) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CANew Law

California Privacy Protection Agency

On May 1, 2025, the CPPA Board voted to support four California bills that expand privacy protections, including restrictions on location data, neural data protections, data broker disclosure requirements, and teleconference meeting provisions. The Board also took a 'support if amended' position on an AI security bill. This is a legislative support action, not an enforcement action.

Low
HHSEnforcement Action

Berkeley Research Group, LLC

Berkeley Research Group, LLC (Business Associate, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Canby Clinic

Canby Clinic (Healthcare Provider, OR) reported a HIPAA breach affecting 549 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Physician Wound Solutions, LLC dba Apollo Medical Supply

Physician Wound Solutions, LLC dba Apollo Medical Supply (Healthcare Provider, FL) reported a HIPAA breach affecting 3,561 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) and the UK Information Commissioner's Office (UK ICO) signed a declaration of cooperation to coordinate international privacy and data protection efforts. The agreement facilitates joint research, sharing of best practices, and mutual collaboration on privacy enforcement across jurisdictions.

Low
CAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) opened a public comment period for proposed Delete Request and Opt-out Platform (DROP) regulations, which will allow California residents to delete their personal information held by CPPA-registered data brokers in a single request. The comment period runs from April 25 to June 10, 2025, with a hybrid public hearing on June 10.

LowData Broker Non-Compliance
HHSEnforcement Action

Carlton County Public Health and Human Services

Carlton County Public Health and Human Services (Healthcare Provider, MN) reported a HIPAA breach affecting 3,502 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Maximus, Inc.

Maximus, Inc. (Business Associate, VA) reported a HIPAA breach affecting 4,955 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Palo Verde Hospital

Palo Verde Hospital (Healthcare Provider, CA) reported a HIPAA breach affecting 594 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Brainard Surgery Center LLC

Brainard Surgery Center LLC (Healthcare Provider, OH) reported a HIPAA breach affecting 1,820 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Icon Family Healthcare LLC

Icon Family Healthcare LLC (Healthcare Provider, CA) reported a HIPAA breach affecting 1,800 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
FLEnforcement Action

Snap, Inc.

Florida Attorney General James Uthmeier filed a lawsuit against Snap, Inc., operator of Snapchat, for violating Florida’s HB3 child social media protection law and the Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The suit alleges Snap knowingly allowed children under 13 to create accounts, failed to obtain parental consent for 14-15 year old users, deployed addictive dark pattern design features to children, and deceived parents about platform risks including predator access, drug sales, and harmful content. The legal action seeks to hold Snap accountable for noncompliance with Florida child safety and privacy laws.

LowChildren's DataConsent FailureNotice Failure
TXEnforcement Action

23andMe

Texas Attorney General Ken Paxton filed a motion to appoint a Consumer Privacy Ombudsman in the Chapter 11 bankruptcy case of 23andMe to protect the sensitive genetic and personal data of Texans. The genetic testing company seeks to sell assets that may include genetic data, health information, and personally identifiable information. The AG's office is also informing Texans of their rights under Texas law to request deletion of their data and genetic samples.

LowBiometric DataUnauthorized Data Sharing

Explore Enforcement Data